Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade com.rabbitmq:amqp-client to version 5.37.0 or higher.
Affected versions of this package are vulnerable to Infinite loop in JSONReader.string() and JSONReader.skipWhiteSpace() in com.rabbitmq.tools.json, neither of which treats CharacterIterator.DONE as a terminator, so the string scanner appends that sentinel without bound and the line comment scanner spins in place. A user able to publish to the RPC request queue can exhaust the heap or pin a thread at full CPU indefinitely, by sending one JSON-RPC message that ends inside a string or a // comment. This requires the application to use the JSON-RPC over AMQP tooling in com.rabbitmq.tools.jsonrpc with the default DefaultJsonRpcMapper, and the condition is not confined to servers, since a client parsing a response from a JSON-RPC service fails the same way.